skills/ahgraber/skills/sdd-sync/Gen Agent Trust Hub

sdd-sync

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions define automated file system tasks including creating directories, writing or overwriting files, and renaming capability folders. These operations are restricted to the project directory and are necessary for the skill's stated purpose of synchronizing documentation.
  • [PROMPT_INJECTION]: The skill processes and acts upon untrusted data from delta specification files, which creates a surface for indirect prompt injection. Ingestion points: Delta specification files located in the changes directory. Boundary markers: The process utilizes specific markers such as ADDED and MODIFIED to delineate and structure content. Capability inventory: The skill has capabilities for local file read, file write, and directory management. Sanitization: There is no explicit sanitization or validation of the specification content described in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 12:44 PM